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FIRST SUBMISSION OF EVIDENCE PAPERS AND NOTES TO PROVE 
POSSIBLE MISCONDUCT BY SBI AGENT RODNEY V. WHITE 
Thursday, December 17, 2015 - 01:44 AM 
ATTN: Representative James L. Boles, Jr. 

N.C. House of Representatives 


RECEIPT CONFIRMATION 
REQUESTED 


URGENT 


300 N. Salisbury Street, Room 528; Raleigh, NC 27603-5925 
Phone: 919-733-5903; Faxed: 919-754-3152; 910-692-8171 (Home) 


Dear the Honorable N.C. Representative James L. Boles, Jr., 

I now hereby submit my first Evidence Statements and 1-Page Brief Letter to 
you and the two other Co-Chairs of the Joint Legislative Oversight Committee on 
Justice and Public Safety. I am attaching 4-Pages to this Letter of State Crime Lab 
documentation that I am excerpting and taking written notes on regarding my 
case. According to the State Crime Lab Documentation, certain procedures have to 
be followed right down to the letter for acceptance of evidence and credible forensic 
analysis procedures. State Bureau of Investigation Special Agent Rodney V. White 
in Greensboro, NC, did not seem to have followed any similar procedure to the 
letter. For child porn to have downloaded to July 28, 2013, a special computer 
forensic analysis tower was not used as outlined in the Crime Lab Document 1 have 
attached. Even if a tower was used, apparently he must have booted up my seized 
Laptop hard drive instead of the approved forensic drive. A computer virus cannot 
run on a computer hard disk drive unless that hard disk was booted up with the 
computer infection and computer virus threats. This letter and attached evidence 
supports my 10-Page Petition + Affidavit. M White screwed that up didn’t he! 

It appears that the State Crime Lab may never have accepted my seized 
Laptop for analysis since Mayodan PD Detective Christopher Todd Brim and 
Reidsville PD Detective Robert Bridge have browsed through my Laptop files 
themselves as they had admitted in the audio of my false confession Aug. 29, 2012. 
Because of this the State Crime Laboratory never would have accepted 
examination as they would have discovered the time stamps dates changing to after 
my computer was seized. Agent White never investigated why child porn 
downloaded to the Laptop after it was seized. Total incompetence or frame up. This 
shoddy forensic analysis does not prove me guilty beyond a reasonable doubt, even 
to a simple child pornography possession charge. I ask that I receive a written or 
verbal confirmation that this Fax was received successfully. Thank You! 




U5.W.G.O. 


Sincerely, 
Brian David Hill 

Former U.S.W.G.O. Alternative News reporter and founder 
Home Phone #: (276) 632-2599 

916 Chalmers St., Apt. D, Martinsville, VA 24112 
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EVIDENCE CONTROL UNIT 


Evidence Control Units in the Raleigh Laboratory and the Western and Triad Regional 
Laboratories ensure proper evidence flow and tracking . The Evidence Control Units receive, 
distribute and return all evidence processed by the State Crime Laboratory. 


Evidence Technicians, and other approved personnel, receive and store ail evidence submitted 
to the Laboratory after the case information is logged into the Laboratory's Forensic Advantage 
(FA) system. The evidence is transferred to the appropriate Laboratory analyst(s) for analysis 
upon request. Generally, the submitting officer will not meet directly with the analyst who wHI 
conduct the analysis. Exceptions to this practice may be made for individual cases when 
circumstances require the submitting officer to talk directly with the analyst(s). If you feel you have 
a special need to discuss certain aspects of your case, you may request such a meeting with the 
analyst(s). 


EVIDENCE ACCEPTANCE POLICY 


SSL mkj crfa* 

Lai ca/nplgt&ly 


The State Crime Laboratory accepts evidence which meets the following criteria: 


• The evidence has been obtained as the result of an official criminal investigation. 

♦ The submitting agency is a law enforcement agency or company/campus police agency 
certified or commissioned through the North Carolina Criminal Justice Education and 
Training Standards Commission, The North Carolina Sheriffs’ Education and Training 
Standards Commission or the North Carolina Company and Campus Police Program. 


• The investigating officer intends to pursue a criminal case pending the results of evidence 
analysis and/or the related investigation. 

* The evidence has not been previously examined by another analyst or laboratory, unless 
prionapprovaT has been requested a nd received from the Crime Laboratory Directo r. 

EVIDENCE SUBMISSION PROCEDURES 


Adherence to proper evidence submission procedures is essentiaj for analysts to evaluate 
evidence properly, to maintain the~chaTn of custod y, and to maintain the physical integrity and 
evidentiary value of subm itted it ems. Failu re to follow the HIabo ratory’s instruc tions when 
submitting evidence could result inlhe evidence being returned unanaiyzedT 

Should you have any questions as to the proper evidence submission procedures, it is always 









Computer Forensics Supplement 
North Carolina State Crime Laboratory 


Version 1 

Effective Date: 7/10/2015 


I jj a * COMPUTER FORENSICS EXAMINATIONS 


5^' 

Under what lawful authority was this evidence seized? 

on kf 22 > f 2012 - 

Condition of the computer at the time of seizure? Qn[ | OFF Q 


□ □ 


S£. 

LAB Number: 

□ 


Search Warrant Court Order Consent 


□ 

Other (Specify): 


Was any attempt made to access the computer (i.e., turn it on or remove anything from it)? NOl I YESl I 
If yes, explain actions taken: /) / / . / ftf ft a A , 1 — ' ‘ ' i 

ffr fat faky sMJm brryftijp Wr p fi /; ce fcf 


M m noonsy iw v p j ' j, J7 m/ce vm. 

Vi'lk JeWk ftwft wk Wrwhjfty c*<futer 

-fiy Ifeml&s, scmSrs, 

Describe in detail the incident and how the computer may have been used in the crime: 

(Attach a copy of the investigative report, if available} . . . / ) ] ft- 

\Mh hiftmje ftvfmi frWnM Me. 

" jify 20-2 lip duty 23 f 203. 


List the date(s) or a date range that should be searched: 


/ ' 


List key words and/or specific items to be searched for during forensic processing: 


List any passwords that may have been used and are known to you: 


List any screen names, user names, e-mail addresses, etc. that are pertinent to the search: 


Note: Any media containing contraband, including evidence hard drives and CDs and discs 
prepared by the State Crime Laboratory, should not be disseminated to anyone other than law 
enforcement in connection with an official investigation and should not be returned to the 
subjects from which it was confiscated. 


Form approved for use by: Timothy 
Suggs 
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Technical Procedure for Evidence Search 

Digital/Latent Evidence Section 

Issued by Digital/Latent Forensic Scientist Manager 



Version 2 
Effective Date: 10/31/2013 


Technical Procedure for Evidence Search 

1.0 Purpose - The purpose of this procedure is to provide a systematic means of searching digital evidence in 
order to find data sought by the search authorization. 

2.0 Scope - This procedure describes the steps to be taken by personnel of the State Crime Laboratory in 
searching computer evidence that is submitted. 

3.0 Definitions 


(^Foi^nsicjWv^ Hard drive containing the operating system and all the forensic software that will be 
use d in the exa mination. 

_ get driv$ X Drive that holds the forensic image of the suspect drive and the case file containing any 
evidence found on the subject drive. 

4.0 Equipment, Materials and Reagents 



5.0 Procedure 


5.1 Read the search authorization (e.g., search warrant or consent) to ensure the scope of search is 
authorized by the document. Install the forensic drive and the target drive into the forensic tower. 

5.2 Ensure that the forensic drive is installed as the primary master and the target drive is installed as 
either the primary slave, secondary master, o r secondary slave. 

5.3 Boot the forensic tower from the forensic drive. 

5.4 Run approved software to undelete any deleted files and recover files and file fragments from 
unallocated space" ” 

5.5 The forensic image of the evidence drive shall be examined for the presence of any deleted partitions 
on the hard drive. If any deleted partitions are noted, these partitions shall be recovered. 

5.6 The forensic image of the evidence drive shall be examined for the presence of any deleted folders on 
the hard drive. Any deleted folders shall be recovered. 

5.7 If using EnCase, a file mounter enscript shall be run to mount any zipped or compressed files so that 
the files contained inside can be examined. 


5.8 A signature analysis shall be run on all files in the case prior to the examination of these files. The 
signature analysis checks the file header information to ensure that the files have not been identified 
with an incorrect file extension. 


5.9 For Cases Involving Images 


- trie). chiUptW searches 


5.9.1 Computer search software or graphics thumbnail software can be used to view images on a 
forensic image. 
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Technical Procedure for Writing Results Statements 

Digital/Latent Evidence Section 

Issued by Digital/Latent Forensic Scientist Manager 


Version 4 
Effective Date: 10/31/2013 


Technical Procedure for Writing Results Statements 


1.0 Purpose - This procedure presents the approved statements that shall be used for reporting digital evidence 
analysis results in the State Crime Laboratory, 


2.0 Scope - This procedure applies to all written result statements for digital evidence analysis in the State Crime 
Laboratory. 

3.0 Definitions 


• Standard Computer Result Statements - Result statements which are common for ail comp uter cases 

regardless of the type o f case being examined. ~ 

• Non-Standard Computer Result Statements - Result statements which vary in their content due to the 
nature of the data being bookmarked and/or due to the nature of the case being worked. 


<s pn psfer SdttJJH 

ik fefern 

rensic Advantage (FA) application ^ ft' I 


4.0 Equipment, Materials and Reagents 

4.1 Equipment and Materials 

• Computer with Forensic Advantage (FA) application 

4.2 Reagents -N/A 


5.0 Procedure -Analyses shall include an accurate interpretation of the actual results of the examination in a 
manner approved by the Forensic Scientist Manager or his/her designee and the Crime Laboratory Director. 
This interpretation may include or build upon one (1) or more of the following responses depending on the 
circumstances of the case and the nature of the digital evidence examination. The order in which the 
statements are arranged is left to the discretion of the Forensic Scientist. Deviations shall be approved 
according to the Laboratory Procedure for Authorizing Deviations. 


5.1 Recovered Disc Reporting Method 

5.1.1 Computer Result Statements 


5.1.1.1 


SSL AftitflaJyey WhuZ CwMle? 

yp mas 'scan 

This report has been generated in association with Item (Item Number), which should 
be viewed in conjunction with this written report. 


5. 1.1.2 No data of interest were located on Item (Item number). 

5.1.13 Item (Item number) was unable to be processed for digital evidence because (reason). 


5.1.1.4 Item (Item Number) was/were scanned for threats using (s oftware) with definitions 
dated (date). The virus scan log is available for review in the “Recovered Wirus Scan 
Logs” folder on Item (Item Number). 

5.1. 1.5 (Number) Encrypted file/files of possible interest was/were recovered from Item (Item 
Number) and is/are available for review in the “Recovered\Encrypted Files” folder on 
Item (Item Number). 
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